← Back

Mcmurtrey Whitaker And Associates

mcmurtrey_whitaker_and_associates

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Cart32
cart32

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcmurtrey Whitaker And Associates
1Cart32
Apr 23, 2026
Oct 6, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file exten...Show more
c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability.Show less
1Mcmurtrey Whitaker And Associates
1Cart32
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.
1Mcmurtrey Whitaker And Associates
1Cart32
Apr 16, 2026
May 3, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.
1Mcmurtrey Whitaker And Associates
1Cart32
Apr 16, 2026
Apr 27, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.
1Mcmurtrey Whitaker And Associates
1Cart32
Apr 16, 2026
Feb 1, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.